← Back to CVE List

CVE-2021-43970

Published: 2022-03-10T17:44Z
Last Modified: 2024-11-21T06:30Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt